CVE-2024-48936
CVE-2024-48936 is a medium-severity vulnerability in Schedmd Slurm with a CVSS 3.x base score of 5.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-863.
Key facts
- Severity: Medium (CVSS 3.x base score 5.0)
- EPSS exploit prediction: 0% (28th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2024-43138
- Weakness: CWE-863
- Affected product: Schedmd Slurm
- Published:
- Last modified:
Description
SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.
Frequently asked questions
- What is CVE-2024-48936?
- SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.
- How severe is CVE-2024-48936?
- CVE-2024-48936 has a CVSS 3.x base score of 5.0, rated medium severity. It is exploitable over network with high attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2024-48936 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (28th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2024-48936?
- CVE-2024-48936 affects Schedmd Slurm. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2024-48936?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2024-48936 have an EU (EUVD) identifier?
- Yes. CVE-2024-48936 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-43138.
- When was CVE-2024-48936 published?
- CVE-2024-48936 was published on 2024-10-28 and last updated on 2026-06-17.
References
- https://lists.schedmd.com/mailman3/hyperkitty/list/slurm-announce%40lists.schedmd.com/message/44MFMN7R35YZFWTNO43R2754W5B5XUAI/
- https://lists.schedmd.com/pipermail/slurm-announce/2024/date.html
- https://www.schedmd.com/security-policy/
Affected products (1)
- cpe:2.3:a:schedmd:slurm:*:*:*:*:*:*:*:*
More vulnerabilities in Schedmd Slurm
- CVE-2023-49937 — Critical (CVSS 9.8): An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a…
- CVE-2023-49934 — Critical (CVSS 9.8): An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed…
- CVE-2022-29502 — Critical (CVSS 9.8): SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
- CVE-2020-27745 — Critical (CVSS 9.8): Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.
- CVE-2019-12838 — Critical (CVSS 9.8): SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
- CVE-2019-6438 — Critical (CVSS 9.8): SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems.
All CVEs affecting Schedmd Slurm →
Other CWE-863 (Incorrect Authorization) vulnerabilities
- CVE-2026-69555 — Critical (CVSS 10.0): Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-71398 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary…
- CVE-2026-27302 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary…
- CVE-2026-48449 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary…
- CVE-2026-48286 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization…
- CVE-2026-48303 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization…
Browse all CWE-863 (Incorrect Authorization) vulnerabilities →